Skip to content
Apache AirflowGHSA-mjqh-v5f2-g2mw

Apache Airflow information exposure vulnerability

High6.5CVE-2023-40712 · Published Sep 12, 2023 · updated Nov 22, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.7.12.7.1
Details and references

Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-airflow-2023-40712, CVE-2023-40712, PYSEC-2023-171

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Sep 122023Apache Airflow Incorrect Authorization vulnerability
CVE-2023-40611Medium4.3fixed in 2.7.1
Aug 232023Apache Airflow missing Certificate Validation
CVE-2023-39441Medium5.9fixed in 2.7.0
Aug 232023Apache Airflow Session Fixation vulnerability
CVE-2023-40273High8.0fixed in 2.7.0rc2
Aug 232023Apache Airflow denial of service vulnerability
CVE-2023-37379High8.1fixed in 2.7.0b1
Aug 112023Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.
CVE-2023-39553High7.5fixed in 2.4.3
Oct 142023Apache Airflow vulnerable to sensitive information exposure
CVE-2023-42663Medium6.5fixed in 2.7.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.